# APT37

> As of 2026-07-19, APT37 is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning apt, campaign, malware. Also known as APT 37, APT-C-28, ATK4, G0067. ATT&CK coverage spans 119 techniques across 17 tactics in 8 of 8 tracked threats. Most-observed techniques: T1140 (Deobfuscate/Decode Files or Information), T1027 (Obfuscated Files or Information), T1113 (Screen Capture).

- **Nation:** North Korea
- **Tracked threats:** 8
- **Categories:** APT, CAMPAIGN, MALWARE
- **Also known as:** APT 37, APT-C-28, ATK4, G0067, Group 123, Group123, InkySquid, Moldy Pisces, Operation Daybreak, Operation Erebus, Reaper, Reaper Group
- **As of:** 2026-07-19

## ATT&CK techniques observed

119 techniques observed across 8 of 8 tracked threats. Tactics: Stealth (formerly Defense Evasion) (23), Collection (16), Discovery (14), Command and Control (10), Initial Access (10), Resource Development (10).

- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 8 of 8 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 7 of 8 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 7 of 8 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 6 of 8 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 6 of 8 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 6 of 8 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 6 of 8 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 6 of 8 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 5 of 8 tracked threats
- [T1123](https://intel.threadlinqs.com/technique/T1123) Audio Capture — Collection — observed in 5 of 8 tracked threats
- [T1010](https://intel.threadlinqs.com/technique/T1010) Application Window Discovery — Discovery — observed in 4 of 8 tracked threats
- [T1025](https://intel.threadlinqs.com/technique/T1025) Data from Removable Media — Collection — observed in 4 of 8 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Collection — observed in 4 of 8 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 4 of 8 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 4 of 8 tracked threats

## Tracked threats

- [APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installer](https://intel.threadlinqs.com/threat/TL-2026-1526) — HIGH
- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-1287) — MEDIUM
- [Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process Injection](https://intel.threadlinqs.com/threat/TL-2026-1285) — HIGH
- [ScarCruft (APT37) Deploys Python-Based NarwhalRAT via Fake Microsoft Account Security Alerts and LNK-in-ZIP Staging with pCloud Dead-Drop C2](https://intel.threadlinqs.com/threat/TL-2026-0890) — HIGH
- [NarwhalRAT: APT37-Linked Python RAT Deployed via Fake Microsoft OTP-Abuse Alerts Against South Korean Targets](https://intel.threadlinqs.com/threat/TL-2026-1525) — HIGH
- [NarwhalRAT: APT37 Python-based RAT delivered via LNK/PowerShell/Python loader chain in Microsoft-themed Korean spear-phishing campaign](https://intel.threadlinqs.com/threat/TL-2026-0802) — HIGH
- [ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame\[.\]com\[.\]cn Targeting Yanbian Ethnic Koreans](https://intel.threadlinqs.com/threat/TL-2026-0460) — HIGH
- [APT37 Ruby Jumper Campaign — Air-Gapped Network Bridging via THUMBSBD USB Worm, RESTLEAF Zoho WorkDrive C2, SNAKEDROPPER Ruby 3.3.0 Runtime Hijack, FOOTWINE/BLUELIGHT Surveillance Backdoors](https://intel.threadlinqs.com/threat/TL-2026-0150) — HIGH

## Related CVEs

1 CVE referenced by tracked APT37 activity.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/APT37
